Information Security Specialist

Contract
On-site
$50-55/hr
San Francisco, CA

Job description

Information Security Specialist
onsite,CA
10+ Years
Client: CA State Client

Mandatory Qualification :

  1. A minimum of five (5) years of experience in Risk and Privacy management, Enterprise Risk
    Management, Insider Threat, Supply Chain Risk Management, Privacy Policies, Procedures, and
    Standards.
  2. Possession of a bachelor’s degree in an IT-related or Engineering field. Additional qualifying
    experience may be substituted for the required education on a year-for-year basis.
    Desired Qualification :
  3. Minimum of four (4) years of experience in developing, implementing, and managing Enterprise
    Risk Management (ERM) programs, including the methodologies, frameworks, and governance
    structures utilized while aligning risk management activities with organization objectives and
    regulatory requirements.
  4. Minimum of four (4) years of experience and advanced-level skills in establishing, governing, and
    overseeing Insider Threat Programs, including the development of policies, governance frameworks,
    risk assessment methodologies, and monitoring processes.
  5. Minimum of four (4) years of experience in developing and implementing risk metrics, key risk
    indicators (KRIs), risk reporting processes, and risk appetite frameworks within a complex
    organization.
  6. Minimum of four (4) years of experience in developing, maintaining, and managing risk
    repositories, including the collection, analysis, and reporting of risk data to support enterprise risk
    management and cybersecurity initiatives.
  7. Minimum of three (3) years of experience in developing and delivering knowledge transfer
    activities, including training sessions, workshops, mentoring, and stakeholder engagement to ensure
    the successful transition of security processes and capabilities.
  8. Minimum of three (3) years of experience in designing, implementing, and governing Insider
    Threat Risks, including alignment with IRS Publication 1075, NIST 800-53, SIMM, SAM 5300 and other
    applicable security and privacy risks.
  9. Minimum of three (3) years of experience in performing quantitative and qualitative risk
    assessments, including the use of impact, likelihood, and velocity factors to evaluate and prioritize
    cybersecurity and enterprise risks.
  10. Minimum of three (3) years of experience in establishing, maintaining, and managing an Enterprise
    Risk Register, including the processes and tools used to identify, document, assess, and track
    information security and enterprise risks.
  11. Minimum of three (3) years of experience supporting audit readiness activities, including the
    development, review, and maintenance of security documentation to ensure compliance with IRS
    Safeguards, California Department of Technology (CDT) Independent Security Assessment (ISA)
    requirements, and other applicable regulatory frameworks.
  12. Minimum of three (3) years of experience in identifying, assessing, monitoring, and mitigating
    risks associated with Personally Identifiable Information (PII) and Federal Tax Information (FTI).

More information

Minimum education level

Bachelor's

Experience level

Expert and leadership (8+years)

Job skills

Network Security

Risk Assessment

Incident Response

Data Encryption

Vulnerability Management

Compliance Auditing

Security Information Systems

Company overview

company-logo
Cloudinfo Inc

IT Services and IT Consulting·51-200 employees

Software Development & IT Consulting and Product Development in various technologies.